Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2021-33037
Published: July 29, 2021
Vulnerability details
The vulnerability allows a remote attacker to preform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests, related to processing of transfer encoding headers. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
JBoss Web Server
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Web Scripting
Ubuntu
openEuler
BIG-IP
SAN Volume Controller and Storwize Family
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Healthcare Translational Research
Oracle Communications Pricing Design Center
Instantis EnterpriseTrack
Traffix SDC
IBM App Connect Professional
Oracle Secure Global Desktop
Oracle Utilities Testing Accelerator
Oracle Managed File Transfer
MySQL Enterprise Monitor
tomcat9 (Debian package)
Tomcat
javapackages-tools
tomcat
tomcat-help
tomcat-jsvc
libtomcat9-embed-java (Ubuntu package)
tomcat9-common (Ubuntu package)
tomcat9 (Ubuntu package)
libtomcat9-java (Ubuntu package)
tomcat-admin-webapps
tomcat-docs-webapp
tomcat-el-3_0-api
tomcat-javadoc
tomcat-jsp-2_3-api
tomcat-lib
tomcat-servlet-4_0-api
tomcat-webapps
tomcat9
Oracle Agile PLM Framework
IBM Engineering Requirements Management DOORS Next
Oracle Graph Server and Client
EMC NetWorker Server
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
IBM Spectrum Virtualize for Public Cloud
IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V5100
IBM FlashSystem V9000
IBM FlashSystem 9100 Family
IBM FlashSystem 9200
IBM FlashSystem 7200
IBM FlashSystem 5200
IBM FlashSystem 5000
IBM Spectrum Virtualize Software
How to mitigate CVE-2021-33037
JBoss Web Server - update to 5.6.0
MySQL Enterprise Monitor - update to 8.0.27
tomcat9 (Debian package) - update to 9.0.31-1~deb10u5
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Oracle Graph Server and Client - update to 21.4
Tomcat - update to D.9.0.87.01
javapackages-tools - update to 2.0.1-13.1
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
SAN Volume Controller and Storwize Family - addressed in versions 8.4.0.5, 8.4.2.0
IBM Spectrum Virtualize for Public Cloud - update to 8.4.2.0
IBM SAN Volume Controller - update to 8.4.2.0
IBM Storwize V7000 - update to 8.4.2.0
IBM Storwize V5000 - update to 8.4.2.0
IBM Storwize V5100 - update to 8.4.2.0
IBM FlashSystem V9000 - update to 8.4.2.0
IBM FlashSystem 9100 Family - update to 8.4.2.0
IBM FlashSystem 9200 - update to 8.4.2.0
IBM FlashSystem 7200 - update to 8.4.2.0
IBM FlashSystem 5200 - update to 8.4.2.0
IBM FlashSystem 5000 - update to 8.4.2.0
IBM Spectrum Virtualize Software - update to 8.4.2.0
tomcat - update to 9.0.10-19
tomcat-help - update to 9.0.10-19
tomcat-jsvc - update to 9.0.10-19
libtomcat9-embed-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9-common (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat9 (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
libtomcat9-java (Ubuntu package) - addressed in versions 9.0.16-3ubuntu0.18.04.2, 9.0.31-1ubuntu0.2
tomcat - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-admin-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-docs-webapp - update to 9.0.36-3.71.1
tomcat-el-3_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-javadoc - update to 9.0.36-3.71.1
tomcat-jsp-2_3-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-lib - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-servlet-4_0-api - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat-webapps - addressed in versions 9.0.36-3.71.1, 9.0.36-3.84.1, 9.0.36-4.63.1, 9.0.36-13.1
tomcat9 - update to 9.0.64-1
EMC NetWorker Server - addressed in versions 19.5.0.4, 19.6.0
External References
Related Security Bulletins
- HTTP request smuggling in Apache Tomcat
- HTTP request smuggling in BIG-IP Apache Tomcat component
- HTTP request smuggling in Traffix SDC Apache Tomcat component
- Debian update for tomcat9
- Amazon Linux AMI update for tomcat8
- IBM App Connect Professional update for Apache Tomcat
- Multiple vulnerabilities in MySQL Enterprise Monitor
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in Oracle Utilities Testing Accelerator
- Multiple vulnerabilities in Oracle Graph Server and Client
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Agile PLM Framework
- Ubuntu update for tomcat9
- Multiple vulnerabilities in Oracle Managed File Transfer
- Multiple vulnerabilities in Oracle Healthcare Translational Research
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- SUSE update for tomcat
- Gentoo update for Apache Tomcat
- Multiple vulnerabilities in Oracle Communications Pricing Design Center
- Multiple vulnerabilities in Oracle Secure Global Desktop
- Multiple vulnerabilities in Instantis EnterpriseTrack
- HTTP request smuggling in in IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem V9000 products
- Multiple vulnerabilities in Dell EMC NetWorker
- Inconsistent interpretation of HTTP requests in IBM SAN Volume Controller and Storwize Family
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- openEuler update for tomcat
- Amazon Linux AMI update for tomcat9
- HP-UX update for Tomcat
- HTTP request smuggling in F5 BIG-IP Apache Tomcat component
- HTTP request smuggling in Traffix SDC Apache Tomcat component